In the April 2024 exploitation of CVE-2024-3400, attackers tried three times to install UPSTYLE, a Python-based backdoor, but Palo Alto Networks Unit 42 says those attempts failed. The actor then used a separate cron-job backdoor to fetch and run commands. The flaw could allow unauthenticated root-level code execution on certain PAN-OS firewalls configured with GlobalProtect; it did not affect every Palo Alto Networks product.
What was CVE-2024-3400?
CVE-2024-3400 was a command injection vulnerability in PAN-OS, Palo Alto Networks’ firewall operating system. Unit 42 described it as enabling an unauthenticated attacker to execute arbitrary code with root privileges on an affected firewall. The vulnerability received a CVSS score of 10.0, a severity rating—not a measure of how many organizations were compromised.
Unit 42 tracked the initial exploitation as Operation MidnightEclipse. The Hacker News reported that exploitation dated to March 26, 2024, and Volexity said it discovered exploitation in the wild on April 10. These are dates from the 2024 incident, not evidence that the campaign is active now.
Which firewalls were in scope?
Unit 42 identified a specific combination of PAN-OS version and GlobalProtect configuration. Having a product from Palo Alto Networks alone did not mean it was affected.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
| Product or configuration | Unit 42’s stated scope |
|---|---|
| PAN-OS 10.2, 11.0, or 11.1 with a GlobalProtect gateway or portal configured | Affected configuration described in the threat brief |
| Cloud NGFW | Not affected |
| Panorama appliances | Not affected |
| Prisma Access | Not affected |
For current product status and version-specific instructions, check Palo Alto Networks’ security advisory. Unit 42 notes that the advisory is updated as information becomes available, so its current guidance takes precedence over this historical incident summary.
Did attackers successfully deploy the Python backdoor?
Not in the observed sequence described by Unit 42: the actor made three unsuccessful attempts to install UPSTYLE. After those failures, the actor used a different backdoor based on a cron job. Unit 42 says the job ran every minute, fetched commands from an external server, and executed them through bash. It could not retrieve the remote scripts, and assessed that the cron backdoor was used for post-exploitation activity.
Rank #2
- Item Package Quantity - 1
- Product Type - ELECTRONIC SWITCH
- This pre-owned product has been professionally inspected, tested and cleaned by Amazon qualified vendors.
- Accessories may not be original, but will be compatible and fully functional. Product may come in generic box.
This distinction matters: the analyzed design of UPSTYLE explains how that malware could operate, but it does not establish that UPSTYLE was successfully installed on every compromised firewall—or that the failed attempts described by Unit 42 succeeded.
How was UPSTYLE designed to work?
In its analysis, Unit 42 described UPSTYLE as a Python script that wrote another script into a Python site-packages .pth location. That nested script decoded embedded Python code. The code looked for attacker commands in a firewall log and placed command output in a legitimate CSS file, using ordinary-looking files as part of its command-and-output path.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
A separate thread restored the CSS file’s original contents after 15 seconds, limiting how long the output remained there. This is the behavior documented for the analyzed backdoor; it should not be confused with proof that the actor’s three observed installation attempts worked.
What activity and impact were reported?
Volexity’s account, as relayed by The Hacker News, described use of a reverse shell, tool downloads, movement into internal networks, and data exfiltration. It also reported efforts involving domain backup DPAPI keys, Active Directory credentials and NTDS.DIT, as well as saved browser cookies and login data. These are reported activities from Volexity’s investigation, not a universal list of what happened on every exposed firewall.
Unit 42 said that, among the cases it responded to, “the vast majority of cases that Unit 42 has responded to have been unsuccessful attempts to exploit the vulnerability and some Level 1 compromises of PAN-OS.” That qualification is important: exposure, attempted exploitation, limited compromise, and interactive access with possible follow-on activity are not interchangeable findings. Unit 42’s brief separates incident severity levels; an organization’s actual impact requires investigation of its own device and network.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should an organization do?
Install a fixed PAN-OS release
Unit 42 listed PAN-OS 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3, plus later versions, as fixed. These are the fixes identified in its incident-era brief. Confirm the currently applicable release and upgrade path in Palo Alto Networks’ security advisory before making a change. Unit 42 strongly advised upgrading even when workarounds or mitigations had already been applied.
Free tools Windows power users keep installed
One-click scans. No signup required.
Investigate for compromise, not just exposure
Apply the advisory’s remediation steps, then assess whether the firewall was exploited and whether activity extended beyond it. Unit 42 recommends monitoring for abnormal activity and investigating unexpected network behavior. Its threat brief also includes threat-hunting queries for Cortex XDR users and indicators associated with the activity.
- Review firewall and network activity for suspicious commands, connections, or other unexpected behavior.
- Check for evidence of persistence or post-exploitation activity, including the cron-job behavior described by Unit 42.
- Consider potential lateral movement from the edge firewall and investigate connected internal systems where findings warrant it.
- Use the current Palo Alto Networks advisory and Unit 42’s threat brief for the applicable indicators and response guidance.
A successful upgrade closes the vulnerability in the installed software; by itself, it does not establish that an already-compromised device is clean. The scale of the campaign was unclear in contemporaneous reporting, so organizations should base their conclusions on device-specific evidence rather than assume either widespread compromise or no impact.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

